Multiple web browsers contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered by an attacker creating a specially-crafted web page that would produce an inactive tab or window to launch a dialog box that appears to come from a trusted source, which could disclose sensitive information resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrades are currently available from these vendors to remediate this vulnerability:
KDE: Upgrade to version 3.3.1
A workaround is available for:
Mozilla
FireFox
Netscape
Opera
Avant Browser
Safari
Maxthon
Internet Explorer for Mac
It is possible to correct the flaw by implementing the following workaround(s):
1. Disable JavaScript
2. Do not visit untrusted and trusted websites at the same time.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.